1. What is this lab used for?


This lab is used to simulate a Security Operations Center (SOC) using a SIEM tool like Splunk.
It allows you to:
- collect logs (Windows, Linux, network, etc.)
- analyze security events
- detect attacks (brute force, malware, intrusion, etc.)
- create automated alerts
- visualize activity using dashboards

In simple terms:
It is a real-time cybersecurity monitoring center.

2. Lab objectives


By the end of this lab, you should be able to:
- Install and configure Splunk
- Add data sources (logs)
- Search events using SPL (Splunk Search Processing Language)
- Build security dashboards
- Detect suspicious activity
- Create automated alerts

3. Tools used

1. Splunk Enterprise / Free
- main SIEM platform
- log analysis tool

2. Data sources
- Windows Event Logs
- Linux logs (auth.log, syslog)
- CSV log files

3. Web browser
- Splunk Web interface

4. Simulated attack data
- SSH brute force attempts
- Windows login failures
- suspicious network traffic

4. Splunk Interface (main tabs)


When you open Splunk Web, you will see the key tabs below:

1. Search & Reporting
Core feature of Splunk
Used for:
- searching logs
- filtering events
- writing SPL queries

Example:
```spl
index=main sourcetype=access_combined
```

2. Dashboards
Data visualization section
Used for:
- charts
- graphs
- security KPIs

Examples:
- failed login attempts
- suspicious IP addresses

3. Alerts
Automated detection system
Used for:
- real-time attack detection
- sending email/notifications

Example:
- more than 10 failed logins → ALERT

4. Data Inputs
Data ingestion section
Used for:
- uploading log files
- connecting Windows/Linux systems
- receiving real-time logs

5. Settings


Global configuration
Used for:
- managing indexes
- users and permissions
- data sources configuration

6. Apps


Extensions for Splunk
Used for:
- adding security modules
- enhancing SOC capabilities

5. Installation steps (click by click)

Step 1: Download Splunk
1. Go to Splunk official website
2. Download Splunk Enterprise (Free trial)

Step 2: Install Splunk
1. Run installer
2. Click Next → Next → Install
3. Wait for installation
4. Create admin account:
- username
- password

Step 3: Launch Splunk
1. Open browser
2. Go to:
```
http://localhost:8000
```
3. Log in

6. Adding data (logs)

Step 1: Go to Data Inputs
- click Settings
- then Data Inputs

Step 2: Choose data source
Options:
- Upload file
- Monitor folder
- TCP/UDP stream

Step 3: Import logs
- select log file
- choose index (main)
- confirm

7. Log analysis (Search)

Step 1: Open Search & Reporting

Step 2: Run queries

Brute force example:
```spl
index=main "failed login"
```

Linux SSH logs:
```spl
index=linux sourcetype=secure
```

Step 3: Filter results
- by IP address
- by user
- by time range

8. Creating dashboards

Step 1:
- go to Dashboards
- click New Dashboard

Step 2:
- name it “Security Monitoring”

Step 3:
- add panels
- use search queries

Examples:
- failed login count
- top attacking IPs

9. Creating alerts

Step 1:
- run a search query

Step 2:
- click Save As → Alert

Step 3:
- set condition:
- event count > 10

Step 4:
- choose action:
- email
- dashboard notification

10. Final lab result


At the end, you get:
- A working SIEM platform
- Centralized log collection
- Attack detection (brute force, anomalies)
- Security dashboards
- Automated SOC alerts

Simple summary
Splunk = SOC brain
Logs = raw data
Dashboards = visualization
Alerts = automatic detection
Search = investigation


 

 

 

 



 

     

      

      
 

      

      

 


 

 

 

       

          

 

Copyright © All rights reserved.

 

     
* Cybersecurity Analyst
* SOC Analyst
* Security Operations Center
* Cloud Security
* DevSecOps
* Information Security
* Cybersecurity Engineer
* Threat Detection
* Incident Response
* SIEM Monitoring

---

# 🛡️ 2. Mots-clés SOC (très importants pour recrutement)

* SOC Analyst Tier 1
* SOC Analyst Tier 2
* Security Monitoring
* Log Analysis
* Security Alerts
* Threat Hunting
* Malware Analysis
* Phishing Detection
* Brute Force Detection
* Incident Investigation
* Security Events
* Blue Team

---

# ☁️ 3. Mots-clés Cloud Security

* Cloud Security Engineer
* AWS Security
* Azure Security
* Cloud Infrastructure Security
* Cloud Threat Detection
* Cloud Monitoring
* Identity and Access Management (IAM)
* Cloud Compliance
* Cloud Security Best Practices

---

# ⚙️ 4. Mots-clés DevSecOps

* DevSecOps Engineer
* Secure CI/CD Pipeline
* Security Automation
* Infrastructure as Code Security
* Docker Security
* Kubernetes Security
* Application Security
* Code Security
* SAST / DAST
* Continuous Security

---

# 🔬 5. Mots-clés techniques (très puissants SEO)

* Splunk
* ELK Stack (Elasticsearch, Logstash, Kibana)
* Microsoft Sentinel
* Wireshark
* Sysmon
* Linux Security
* Windows Security Logs
* Network Security
* Firewall Logs
* IDS / IPS

---

# 🚀 6. Mots-clés “portfolio / recrutement”

👉 Très important pour être trouvé par RH

* Cybersecurity Portfolio
* SOC Analyst Portfolio
* Cybersecurity Projects
* Cybersecurity Labs
* Security Use Cases
* Threat Detection Lab
* Cybersecurity Skills
* Entry Level Cybersecurity
* Junior Cybersecurity Analyst

---

# 📈 7. Mots-clés SEO longue traîne (ULTRA PUISSANT)

👉 Ceux-là font la différence 🔥

* Cybersecurity analyst portfolio website
* SOC analyst projects and labs
* How to detect cyber attacks using SIEM
* Cybersecurity incident response examples
* Cloud security best practices for beginners
* DevSecOps security pipeline example
* SIEM log analysis tutorial
* Threat detection use cases

---

# 🧠 STRATÉGIE SEO (très important)

## 📌 Où mettre ces mots-clés :

* Page d’accueil (titre + description)
* Page “About”
* Page “Labs”
* Titres H1 / H2 / H3
* Meta description
* URL des pages

---

# 🏆 EXEMPLE DE TITRE SEO (à utiliser)

👉
**Cybersecurity Analyst Portfolio | SOC, Cloud Security & DevSecOps Projects**

---

# 🏆 EXEMPLE META DESCRIPTION

👉
**Cybersecurity Analyst portfolio with hands-on labs in SOC monitoring, SIEM, Cloud Security and DevSecOps. Available for hiring.**

---
 

Manager DSI (secteur bancaire)

🎯 Mots-clés principau

# 🏦 🔥 1. Mots-clés Manager DSI (secteur bancaire)

## 🎯 Mots-clés principaux

* IT Manager
* IT Director
* Head of IT
* IT Governance
* Information Systems Management
* Digital Transformation
* IT Strategy
* Enterprise IT

---

## 🏦 Spécifique BANQUE (très puissant)

* Banking IT Systems
* Core Banking Systems
* Financial Information Systems
* Banking Cybersecurity
* Risk Management Banking
* IT Compliance Banking
* Data Protection Banking
* Financial Security

---

## ⚖️ Gouvernance & conformité

* IT Governance Framework
* COBIT
* ITIL
* Risk Assessment
* Business Continuity Plan (BCP)
* Disaster Recovery Plan (DRP)
* Regulatory Compliance

---

## 📊 Management & pilotage

* IT Project Management
* Team Leadership IT
* IT Operations Management
* KPI IT Performance
* IT Service Management (ITSM)
* Strategic IT Planning

---

# 🏥 🛡️ 2. Mots-clés RSSI (hôpital / santé)

## 🎯 Mots-clés principaux

* Chief Information Security Officer (CISO)
* Information Security Manager
* Cybersecurity Governance
* Security Risk Management
* Security Policies

---

## 🏥 Spécifique SANTÉ (très important)

* Healthcare Cybersecurity
* Hospital Information Systems (HIS)
* Patient Data Protection
* Medical Data Security
* Health IT Security
* Electronic Health Records (EHR) Security

---

## 🔐 Sécurité & conformité

* ISO 27001
* NIST Cybersecurity Framework
* GDPR Compliance
* Data Privacy
* Access Control
* Identity Management

---

## 🚨 Gestion des incidents

* Incident Response Management
* Security Operations Management
* Cyber Risk Assessment
* Vulnerability Management
* Threat Intelligence

---

# 🚀 🧠 3. Mots-clés hybrides (TRÈS PUISSANTS 🔥)

👉 Ceux-là font le lien entre ton profil actuel et ton évolution :

* Cybersecurity Leadership
* IT Security Strategy
* Enterprise Security Architecture
* Security Governance
* IT Risk Management
* Digital Security Transformation
* Cloud Security Governance